The future of data transfers between the EU and the United States seems more uncertain than ever
Recent decisions by President Donald Trump call into question the Transatlantic Data Privacy Framework (TADPF), an agreement that governs the transfer of personal data between the European Union and the United States. By dismissing several Democratic members of the Privacy and Civil Liberties Oversight Board (PCLOB), a key body intended to oversee privacy protections in the face of American surveillance laws, the American administration is weakening a fundamental pillar of this agreement.
Since Edward Snowden's revelations, it has been established that the United States practices mass surveillance by collecting personal data from large European technology companies. The EU adequacy decision relies in part on US oversight mechanisms, including the PCLOB, when assessing whether Europeans receive essentially equivalent protection.
By this presidential decision, the independence of this body is compromised because its operation requires a minimum of active members. If the PCLOB becomes inoperative, it could make the use of American cloud services by EU companies, administrations and educational establishments illegal. Apple, Google, Microsoft or Amazon would be directly affected.
Why the framework remains vulnerable
The history of data transfers between the EU and the United States is marked by successive cancellations of previous agreements. After the invalidation of the Safe Harbor in 2015 (Schrems I) and the Privacy Shield in 2020 (Schrems II), the TADPF was adopted in 2023 despite persistent criticism. Unlike GDPR requirements, it relies on executive orders rather than actual legislation.
This agreement is considered “fragile” and often controversial, believing that it can be revoked with the stroke of a pen by a new US administration. This is precisely what is looming: one of President Donald Trump's first decisions was to review and potentially reverse all of his predecessor's national security decisions within 45 days.
What future for European data?
As long as the agreement is not officially canceled by the European Commission or invalidated by the Court of Justice of the EU, companies can continue to use it. But with the gradual collapse of its foundations, they must prepare an emergency plan to host their data in a sovereign manner.
If the TADPF were to fall, it could mark a major rupture in transatlantic digital relations, with an impact similar to that of the American debate on TikTok. Ultimately, large American technology companies could be forced to protect the data of European citizens against access by the American government, or risk being excluded from the European market.
The European Commission, for its part, finds itself in a delicate position. In the event of inaction, it risks jeopardizing the legal compliance of European companies. But any official challenge to the TADPF could provoke a confrontation with the Trump administration and the American digital giants.
To learn more about French alternatives, discover our sovereign cloud solution.